The GDI component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office for Mac 2011, and Office 2016 for Mac allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI Information Disclosure Vulnerability."
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-148
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-146
http://www.securitytracker.com/id/1037441